Legal
Data Processing Agreement
Last updated: 15 June 2026 · GDPR-compliant DPA between FinovaOS and its customers
This Data Processing Agreement governs how FinovaOS processes personal data on behalf of customers. By using FinovaOS, you agree to this DPA as a legally binding addendum to the Terms of Service. This DPA is effective from the date you first use the FinovaOS platform.
📋 Scope and Application
Purpose
This Data Processing Agreement ('DPA') supplements the FinovaOS Terms of Service and governs the processing of personal data by FinovaOS ('Processor') on behalf of the customer ('Controller') in connection with the FinovaOS platform.
GDPR Compliance
This DPA is intended to comply with the requirements of the EU General Data Protection Regulation (GDPR) Regulation (EU) 2016/679, the UK GDPR, and other applicable data protection laws.
Who This Applies To
This DPA applies to any customer that: (a) is established in the European Economic Area or United Kingdom; (b) processes personal data of EEA/UK residents; or (c) specifically requests a DPA for compliance purposes.
🔑 Roles and Responsibilities
Customer as Controller
The customer determines the purposes and means of processing personal data entered into FinovaOS — including employee records, customer contact information, and supplier details. The customer is the 'Data Controller' under GDPR.
FinovaOS as Processor
FinovaOS processes personal data only on documented instructions from the customer (as expressed through use of the platform and this agreement). FinovaOS is the 'Data Processor'.
Sub-processors
FinovaOS uses approved sub-processors to deliver the service, including: Supabase (database & storage), Vercel (application hosting), LemonSqueezy (payments & checkout), SMTP email provider (transactional email), and Twilio/BulkSMS providers (SMS notifications). A current list is maintained at finovaos.app/legal/sub-processors.
🛡️ Security Measures
Technical Measures
FinovaOS implements the following technical safeguards: TLS 1.3 encryption in transit, AES-256 encryption at rest, field-level encryption for sensitive data (NTN, CNIC, bank details), role-based access control, multi-factor authentication support, and immutable audit logs.
Organisational Measures
Access to customer data is restricted to authorized personnel on a need-to-know basis. All staff with data access undergo background checks and sign confidentiality agreements. Security training is conducted annually.
Incident Notification
FinovaOS will notify the customer without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach affecting customer data, including: nature of breach, categories of data affected, likely consequences, and measures taken or proposed.
🌍 International Data Transfers
Transfer Mechanisms
Where personal data is transferred outside the EEA or UK, FinovaOS relies on Standard Contractual Clauses (SCCs) approved by the European Commission, or an equivalent lawful transfer mechanism, to ensure adequate protection.
Data Locations
Customer data is stored in: AWS eu-west-1 (Ireland) for EU customers, AWS ap-south-1 (Mumbai) for South Asia, AWS me-south-1 (Bahrain) for Middle East. Customers may request geographic data residency restrictions for Enterprise plans.
👤 Data Subject Rights
Assisting the Controller
FinovaOS will assist the customer in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) by providing appropriate tools in the platform and technical support where needed.
Erasure
Upon customer request or account closure, FinovaOS will delete or anonymise all personal data within 90 days, except where retention is required by law. Backup copies are purged within 180 days.
Data Portability
Customers can export all personal data (contacts, employee records, transaction parties) in CSV format at any time via the dashboard export feature.
📊 Audit Rights
Audit & Inspection
Upon 30 days written notice, the customer may conduct (or commission a qualified third party to conduct) an audit of FinovaOS data processing activities. FinovaOS will cooperate with audits during normal business hours and may require a non-disclosure agreement before sharing sensitive infrastructure details.
Compliance Reports
In lieu of an on-site audit, FinovaOS will provide copies of relevant security certifications, penetration test summaries, and compliance reports on request, subject to confidentiality obligations.
To execute a signed DPA for enterprise agreements, contact legal@finovaos.app